manawize

The dangers of public Wi-Fi

Public Wi-Fi is convenient, but it can also be dangerous. We’ll show you when 2FA isn’t enough, and how you can protect your accounts. Practical advice, made simple.
Public Wi-Fi and two-factor authentication: what every user needs to know
A familiar situation: using the airport Wi-Fi

Imagine this: you’re at the airport, waiting for your flight, and it occurs to you that you still need to make a quick bank transfer or log into your work email account. You see „Airport_FreeWiFi – open network” on the screen. One click, and you’re connected. Convenient, quick and free.

But is it safe as well?

This scenario is repeated millions of times a day all over the world. In cafés, hotels, shopping centres and libraries. Public Wi-Fi is now almost a basic service. However, what is convenient is not always secure, and this is particularly true of open networks.

Why is public Wi-Fi so appealing, and why does it pose risks?

The main advantage of public Wi-Fi is clear: you don’t have to use up your mobile data allowance, the connection is usually fast, and it’s available free of charge. It can be a real help when travelling, outside of work, or whilst waiting for a long time.

The problem is that, in most cases, these networks they are not encrypted, or they are protected by a password known to everyone, which is almost the same as if they were completely open. This means that anyone on the same network with the right technology can intercept the data traffic.

Think of it as having a phone conversation in a crowded café: if you speak loudly, the people sitting at the next table will be able to hear what you’re saying.

How can attackers exploit a public network?

The literature on cyber security and organisations such as the CISA (the US Cybersecurity and Infrastructure Security Agency) or the OWASP Several typical attack methods used in public Wi-Fi environments have been identified. We summarise the most important ones in simple terms.

Man-in-the-middle attack

The most common and most serious threat. An attacker „intercepts” the connection between your device and the internet: all the data you send or receive passes through the attacker’s machine without you realising it. Think of it as a postman who opens your letter, reads it, then seals it back up and passes it on, and you have no idea that this has happened.

Fake networks (Evil Twin)

The attacker sets up a network with a name that is almost identical to that of a genuine, trustworthy network. For example, in a café, you might find „CaféWifi” and „CafeWifi” side by side. If you accidentally connect to the fake one, all your traffic will be routed through the attacker.

Session Hijacking

This is the type of attack that is particularly worth paying attention to, and which is explained in detail in our video on the subject.

When you log in to a website or app, the server assigns a unique, temporary identifier – known as a session token – to your device. This „active connection” maintains your logged-in status. An attacker often doesn’t even need your password: all they need to do is obtain this active session token. They can then log into your account as if they were you, without knowing your password or your 2FA code.

To use an analogy, it’s like a safe that’s been left open: if someone gets hold of it whilst the door is already open, they no longer need the combination, even if there is a lock on it.

A quick login over your lunch break using a café’s guest Wi-Fi could be enough for this to happen, whilst you’re under the impression that you’ve gone about your business safely.

Why does two-factor authentication not provide complete protection on its own?

A two-factor authentication (2FA) one of the most effective and highly recommended security solutions. This is confirmed by all reliable sources, including the NIST (the US National Institute of Standards and Technology) also emphasises this. The essence of 2FA is that, in addition to a password, it requires a second form of authentication: for example, a code sent via text message, a number generated by an authentication app, or a physical security key.

This does indeed provide significant protection, but it does not provide complete safety in every situation.

When is 2FA not enough?

In the event of a work process diversion: If you have already logged in and an attacker obtains your session token, 2FA no longer provides protection. You have already logged in, and the token is valid. This is precisely the scenario that is most difficult to prevent on public Wi-Fi.

In the event of real-time data theft: An attacker can „intercept” communications in real time between your device and the genuine website via a public network. You enter your password and 2FA code, and the attacker immediately forwards them to the genuine site, obtains the session token, and then takes control of your account. The whole process takes just a few seconds.

In the case of a SIM swapping attack: Although this isn’t directly related to Wi-Fi, it’s worth noting that SMS-based two-factor authentication (2FA) can be bypassed by obtaining your phone number. That’s why it’s a good idea to use an authentication app instead of SMS.

In summary: 2FA is an essential layer of security, but it is no substitute for exercising caution when using public networks. The two work effectively together, rather than one in place of the other.

Which accounts are most at risk?

Not all accounts pose the same level of risk, but the following are particularly vulnerable on public Wi-Fi:

  • Email accounts: Email is the „key” to almost every other account. Most password recovery processes rely on it. If an email account is compromised, all your other accounts could be at risk.
  • Banking and financial applications: Direct financial loss may occur if an attacker gains access to online or mobile banking.
  • Social media accounts: Personal data, messages and networks of contacts may fall into the wrong hands. For businesses, a hacked corporate social media profile can cause serious damage to their reputation.
  • Corporate accounts (VPN, internal systems, email): In small businesses, it is particularly dangerous if an employee accesses the company’s systems via a public Wi-Fi network, as this puts the entire company’s data at risk.
What signs might indicate a suspicious network?

Here are a few warning signs to look out for:

  • A network with a similar name, but one that is unknown: If several networks with similar names appear in the same place at the same time (e.g. „HotelWifi” and „Hotel_Wifi”), one of them may be a fake.
  • Password-free, open network: It is particularly suspicious if it describes itself as something that is not usually public knowledge (e.g. the name of a bank or a government institution).
  • Browser security warnings: If your browser displays a „Not secure” warning or a certificate error, do not continue.
  • Unusually slow connection: It is not always a sign of an attack, but in the case of a man-in-the-middle attack, data traffic may be slower as it passes through an intermediary.
  • A login page is required to access the Wi-Fi: A so-called „captive portal” is not in itself suspicious, but if it redirects you to an unfamiliar, strange-looking page, it is worth being cautious.
What can you do to help protect them?

The good news is that the risks can be significantly reduced by following a few simple steps. In line with the recommendations of CISA and NIST, we recommend the following:

Use mobile data for sensitive operations

If you’re carrying out banking transactions, logging into your work system or sending an important email, switch off Wi-Fi and use your mobile network instead. The mobile network is much harder to intercept than an open Wi-Fi network.

Use a VPN

A VPN (Virtual Private Network) It creates an encrypted „tunnel” between your device and the server, so even if someone is monitoring the traffic, they will only see encrypted, unreadable data. Using a reliable, paid VPN service is strongly recommended, particularly for business users.

Turn off automatic Wi-Fi connection

Many smartphones automatically connect to known or open networks. It’s worth turning this feature off so that you can choose for yourself when and to which network you connect.

Avoid making important logins on public networks

The „just a minute” mindset is the most dangerous. Unless it’s absolutely necessary, don’t log in to your bank, work or email accounts via public Wi-Fi.

Use two-factor authentication wisely

You should definitely enable 2FA on all your important accounts, particularly your email, online banking and work systems. Where possible, choose an authentication app (e.g. Google Authenticator, Microsoft Authenticator) rather than SMS-based codes, as app-based solutions are more resilient to certain types of attack.

Keep your devices and apps up to date

Regular updates do more than just introduce new features: fixing security vulnerabilities is one of their most important tasks. An unpatched device is prone to known vulnerabilities, which attackers can easily exploit – whether on a public network or not.

In summary: awareness is the best defence

Public Wi-Fi isn’t the work of the devil, and it shouldn’t be viewed as a nightmare. At the same time, it’s important to understand that an open network always poses a higher risk than your own password-protected home or office connection. 

Two-factor authentication is indeed one of the most effective security measures available today, but it is not a magic bullet. On public networks, additional risks may arise – particularly in the form of session hijacking – against which 2FA alone does not provide complete protection.

The good news is that by adopting a few simple habits – such as using a VPN and mobile data for sensitive activities, disabling automatic connections, keeping your software up to date, and using two-factor authentication (2FA) wisely – most risks can be reduced to a manageable level.

Cybersecurity is not just a single lock on the gate, but a combination of layers that reinforce one another. The more layers you use, the harder it will be for anyone trying to bypass them.

Don’t have time to read through all the details? We’ve also covered the topic in a short, comprehensive video, highlighting the key points. You can watch it here:

Our latest blog posts:

Share it with others!

How can we help your company?

Have a question?
Would you like to give us a try?
Feel free to write to me!

Are you ready for the next step? Request a personalised quote now!
We will get back to you within 24 hours.

IT Service Request Form – New Gen
Adatvédelmi áttekintés

Ez a weboldal sütiket használ, hogy a lehető legjobb felhasználói élményt nyújthassuk. A cookie-k információit tárolja a böngészőjében, és olyan funkciókat lát el, mint a felismerés, amikor visszatér a weboldalunkra, és segítjük a csapatunkat abban, hogy megértsék, hogy a weboldal mely részei érdekesek és hasznosak.